Uvdesk maintains a help-desk and customer-support ticketing platform with a narrow product footprint centered on its Community Skeleton offering, which serves small to medium-sized organizations managing customer interactions. The recurring vulnerability signal centers on web application input handling and access-control issues, including cross-site scripting, excessive authentication-attempt tolerance, and unrestricted file uploads, reflecting the web-facing nature and user-interaction complexity of ticketing systems. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Uvdesk over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-0265HIGH Uvdesk version 1.1.1 allows an authenticated remote attacker to execute commands on the server. This is possible because the application does not properly validate profile pictures | Apr 4, 2023 | 8.8 | 28 | NO | NO |
CVE-2023-37635CRITICAL UVDesk Community Skeleton v1.1.1 allows unauthenticated attackers to perform brute force attacks on the login page to gain access to the application. | Oct 23, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-0325MEDIUM Uvdesk version 1.1.1 allows an unauthenticated remote attacker to exploit a stored XSS in the application. This is possible because the application does not correctly validate the | Apr 4, 2023 | 6.1 | 21 | NO | NO |
CVE-2023-1197MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository uvdesk/community-skeleton prior to 1.1.0. | Mar 6, 2023 | 4.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Uvdesk.
Media articles that mention a CVE ID that affects a product developed by Uvdesk — matched by CVE ID, not by vendor name.